| Registry / Cultiva | Supported |
|---|---|
| Registry 3.5.x + Cultiva 2.0.x · Rowan (PLE1) | Yes |
| Registry 3.0.x–3.4.x + Cultiva 1.7.x | Best effort |
| Registry 2.x + Cultiva 1.1.x | Best effort |
| Older | No |
Do not open a public GitHub issue for security vulnerabilities.
Report to the main Cultiva security policy:
github.com/krwg/cultiva/blob/main/SECURITY.md
Email: shevotsukov@icloud.com
Email shevotsukov@icloud.com with:
- Plugin id and version
- Description and impact
- Steps to reproduce
- Affected Cultiva version(s)
You may also use the Security alert template — maintainers will convert it to a private thread if needed.
Report to the plugin author or registry maintainer. Cultiva core is not responsible for unofficial registries.
In scope for this repo:
- Malicious or vulnerable code in official plugin folders
- Incorrect or tampered
sha256entries inregistry.json - Supply-chain issues in the published manifest / baseUrl chain
Out of scope:
- Bugs that are not security issues (use regular bug reports)
- Open-Meteo, SomaFM, or other third-party service availability
- Issues requiring physical access to an unlocked machine
We aim to acknowledge reports within 72 hours and provide a status update within 14 days.
Fixed plugin issues are released via updated registry versions and recomputed sha256 hashes.